Your SlideShare is downloading. ×
LimitsNot railsAbout groups, rules and defectorsJurgen van der VlugtDialogues House Amsterdam, 6 June 2013
Introduction• Jurgen = Ir.drs. J. van der Vlugt RE CISA CRISC• Plus the usual disclaimer that this is Work In Progress• So...
Agenda• Rails• Rubbish• Reactions• Radicals• Guiding rails• Risk ‘Management’
Rails
RailsPeople-less Process & Technology
Rubbish →
(FUD)
Reactions to rules
Response
Range
Reaction;ratio (!) and psycho
Radicals• Extremist-bureaucrats• Defectors• ALWAYS• They belong!• Keep it fresh!• So keep them close…?
Freedom through guiding railsDe scheef is niet van caouchouc
Guiding rails
Societal pressures; effective design• Understand the societal dilemma• Consider all four societal pressures• Pay attention...
Clear requirements
Resilience
Pt > Dt + Rt(Pt > 0)E = Dt + Rt(Pt = 0) →Zero-day exploits, orany unknown vectors(Note:• Clusterfucks• FUQedBoy scout mode...
Conclusion: Risk ‘Management’• Biases (list)• Notice the weak signals• Be creative• Don’t be a dictator (guiding rails)• C...
Hope you enjoy(ed) the rideThat was all. Thank you.
Dank u
Further Reading
• Jvdvlugt@maverisk.nl• LinkedIn http://nl.linkedin.com/in/jurgenvandervlugt/• Twitter @jvdvlugt• (G+, Pinterest, Tumblr, ...
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
ISSA NL event 2013 06 06 Limits, Not Rails
Upcoming SlideShare
Loading in...5
×

ISSA NL event 2013 06 06 Limits, Not Rails

86

Published on

On the necessary re-design of security controls. To provide guiding rails to keep only those that sway too far out, instead of slamming everyone into compliance with too-tight rails.

Published in: Business
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
86
On Slideshare
0
From Embeds
0
Number of Embeds
1
Actions
Shares
0
Downloads
0
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide

Transcript of "ISSA NL event 2013 06 06 Limits, Not Rails"

  1. 1. LimitsNot railsAbout groups, rules and defectorsJurgen van der VlugtDialogues House Amsterdam, 6 June 2013
  2. 2. Introduction• Jurgen = Ir.drs. J. van der Vlugt RE CISA CRISC• Plus the usual disclaimer that this is Work In Progress• So, questions please
  3. 3. Agenda• Rails• Rubbish• Reactions• Radicals• Guiding rails• Risk ‘Management’
  4. 4. Rails
  5. 5. RailsPeople-less Process & Technology
  6. 6. Rubbish →
  7. 7. (FUD)
  8. 8. Reactions to rules
  9. 9. Response
  10. 10. Range
  11. 11. Reaction;ratio (!) and psycho
  12. 12. Radicals• Extremist-bureaucrats• Defectors• ALWAYS• They belong!• Keep it fresh!• So keep them close…?
  13. 13. Freedom through guiding railsDe scheef is niet van caouchouc
  14. 14. Guiding rails
  15. 15. Societal pressures; effective design• Understand the societal dilemma• Consider all four societal pressures• Pay attention to scale• Foster empathy & community• Use security systems to scale• Harmonize institutional pressures• Ensure fin.penalties ~ detection likelihood• Choose general, reactive sec.systems• Reduce power concentrations• Require transparency
  16. 16. Clear requirements
  17. 17. Resilience
  18. 18. Pt > Dt + Rt(Pt > 0)E = Dt + Rt(Pt = 0) →Zero-day exploits, orany unknown vectors(Note:• Clusterfucks• FUQedBoy scout model!Guiding rails
  19. 19. Conclusion: Risk ‘Management’• Biases (list)• Notice the weak signals• Be creative• Don’t be a dictator (guiding rails)• Clear requirements• Be Prepared!
  20. 20. Hope you enjoy(ed) the rideThat was all. Thank you.
  21. 21. Dank u
  22. 22. Further Reading
  23. 23. • Jvdvlugt@maverisk.nl• LinkedIn http://nl.linkedin.com/in/jurgenvandervlugt/• Twitter @jvdvlugt• (G+, Pinterest, Tumblr, etc.etc.)“I hate quotations” (Ralph Waldo Emerson 1849, quoted by Rem Koolhaas in S, M, L, XL, 1995)Contact detailsDogma: The problem starts at the secondary level, not with theoriginator or the developer of the idea but with the people who areattracted by it, who cling to it until their last nail breaks, and whoinvariably lack the overview, flexibility, imagination, and, mostimportantly, sense of humor, to maintain it in the spirit in which it washatched. Ideas are made by masters, dogma by disciples, and theBuddha is always killed on the road. (Tom Robbins, Still Life withWoodpecker, 1984)

×